Privacy Policy
Last updated: 22 August 2026
In short
- We are a European project and we process your data under the GDPR, Regulation (EU) 2016/679.
- We collect what we need to run your account, your bookings and your reviews, and nothing more.
- We never sell personal data and we run no advertising or cross-site tracking cookies.
- You can access, correct, export or delete your data at any time, on your own, from your profile.
Manage everything in one place on the privacy choices page.
1. Who we are (data controller)
HosPet.eu ("we", "us") operates a platform for discovering, reviewing and booking pet-friendly stays in Europe. We are the data controller for the personal data described here. Contact for any privacy matter, including the rights in section 8: info@hospet.eu. We have not appointed a Data Protection Officer, as we are not required to under Art. 37 GDPR; the address above reaches the person responsible.
2. What we collect and where it comes from
Almost everything we hold comes from you: what you type into an account, a booking, a review, the newsletter form or a message to us. Two exceptions: your booking status and confirmation come back from our travel partner, and property information comes from the property and from our suppliers. We do not buy personal data and we do not build profiles about you.
We do not knowingly collect data from children under 16. We ask for no special category data (Art. 9 GDPR), so please keep health or similar details out of your reviews and messages.
3. Why we process it, on which legal basis, for how long
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Create and run your account | Name, email, password hash, profile details, pet types | Contract, Art. 6(1)(b) | Until you delete your account |
| Process and manage a booking | Guest name, email, phone, nationality, stay details, booking reference | Contract, Art. 6(1)(b) | Duration of the stay, then up to 10 years where tax or accounting law requires it |
| Take payment and prevent fraud | Payment status, amount, currency (card data never reaches us) | Contract, Art. 6(1)(b); legal obligation, Art. 6(1)(c) | As required by accounting law |
| Publish your reviews | Review text, rating, pet details you choose to add, display name | Contract, Art. 6(1)(b); legitimate interest in a trustworthy platform, Art. 6(1)(f) | Until you delete the review or your account |
| Send the newsletter | Email address, subscription date, consent record | Consent, Art. 6(1)(a) | Until you unsubscribe or withdraw consent |
| Answer your messages and partnership enquiries | Name, email, organisation, message | Legitimate interest in replying to you, Art. 6(1)(f) | Up to 24 months after the last message |
| Keep the site secure and prevent abuse | IP address, request metadata, rate-limit counters, captcha results | Legitimate interest in security, Art. 6(1)(f) | Up to 12 months |
| Prove that you consented, and to what | Consent type, date, document version, source, IP and browser | Legal obligation to demonstrate consent, Art. 7(1) and 5(2) | 5 years after the consent is withdrawn |
| Understand how the site is used | Anonymous usage statistics | Consent, Art. 6(1)(a), via the cookie banner | Until you withdraw consent |
Where we rely on legitimate interest we have weighed it against your rights and you can object at any time (section 8). Where we rely on consent you can withdraw it at any time, and withdrawing is as easy as giving it; withdrawal does not affect processing already carried out.
4. Who we share it with
Only with the parties below, each bound by a data processing agreement under Art. 28 GDPR or acting as an independent controller for its own service. We do not sell personal data and we do not share it for advertising.
| Recipient | Role | Location |
|---|---|---|
| Nuitée / LiteAPI | Booking fulfilment: passes the guest details the hotel needs to hold your room | EU and third countries under SCCs |
| The property you book | Provides the accommodation and applies its own pet policy | Country of the property |
| Stripe | Payment processing and fraud prevention. Card data is entered in their portal and never reaches our servers | EU / US, SCCs and their own certifications |
| Resend | Transactional email and newsletter delivery | EU / US, SCCs |
| InsForge (database and storage) and Fly.io (hosting) | Run the platform infrastructure on our behalf | EU regions where available, SCCs otherwise |
| GetYourGuide | Only if you click one of our activity links, which carry an affiliate identifier and no personal data | EU |
We may also disclose data where the law obliges us to, for example to a competent authority acting within its powers.
5. Transfers outside the EEA
We keep data in the EEA wherever the provider offers it. When a provider processes data in a third country, the transfer relies on an adequacy decision under Art. 45 GDPR or on the European Commission's Standard Contractual Clauses under Art. 46, with supplementary measures where needed. If you book a property outside the EEA, your booking details necessarily travel to that property so it can host you, under Art. 49(1)(b).
6. Cookies
We use strictly necessary cookies to run the site, and optional ones only with your consent. The full list, the lifetimes and the way to change your mind are in the Cookie Policy.
7. How we protect it
Traffic is encrypted in transit (HTTPS with HSTS), passwords are stored hashed and never in clear text, database access is locked down row by row, admin areas require authentication, and sensitive operations are rate-limited. Access to production data is limited to the people who need it. If a breach ever puts your rights at risk, we notify the supervisory authority within 72 hours and tell you without undue delay, as Art. 33 and 34 GDPR require.
8. Your rights
- Access (Art. 15): a copy of the data we hold about you.
- Rectification (Art. 16): correct anything inaccurate, directly in your profile.
- Erasure (Art. 17): delete your account and data from your profile, in two clicks and an email confirmation.
- Restriction (Art. 18) and objection (Art. 21), including to any processing based on legitimate interest.
- Portability (Art. 20): your data in a structured, machine-readable format.
- Withdraw consent (Art. 7(3)) for the newsletter or optional cookies, at any time.
- No automated decision-making: we run none of the profiling or automated decisions described in Art. 22.
Write to info@hospet.eu and we answer within one month (Art. 12(3)), extendable by two months for complex requests, which we would tell you about. Exercising your rights is free. You also have the right to lodge a complaint with the data protection authority of your country of residence, workplace or of the alleged infringement (Art. 77).
9. Changes to this policy
If we change how we process your data we update this page and its date, and for anything material we tell you before the change takes effect, by email or a notice on the site.